Mobile Device Management Agent Policy Enforcement

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current mobile device management systems lack comprehensive control over mobile devices, especially in enforcing policies across various environments and applications, leading to security and resource access issues.

Innovation Solution

A method and apparatus for implementing mobile device management policies that utilize a mobile device management agent to monitor and enforce policies across different device states, application tunneling functionalities, and device clouds, ensuring secure access to enterprise resources while maintaining user privacy.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If mobile device management systems implement comprehensive policy control across all devices and applications, then security and resource access control are improved, but device complexity and system overhead increase

Engineering Contradiction:
Improvesecurity controlVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces an MDM agent as an intermediary component that runs on mobile devices to enforce management policies. This agent acts as a mediator between the mobile device and the MDM server, handling policy evaluation and enforcement locally while maintaining communication with the central management system. This approach improves security control by ensuring policies are enforced consistently across all devices while managing complexity by localizing policy execution rather than requiring centralized control of all device operations.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If mobile device management systems monitor and enforce policies across all device states and applications, then policy enforcement capability is improved, but processing overhead and energy consumption increase

Engineering Contradiction:
Improvepolicy enforcement capabilityVSAvoidenergy consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The MDM agent monitors device state changes and evaluates policies based on these changes rather than continuously monitoring all device operations. The system periodically checks for state transitions (such as application launches, network connections, or device state changes) and only then evaluates applicable policies. This periodic monitoring approach maintains strong policy enforcement capability while significantly reducing processing overhead and energy consumption compared to continuous monitoring.

Inventive Principle:
Principle #19Periodic action

3Reliability

If mobile device management systems apply strict policies across all environments, then security control is improved, but user flexibility and ease of operation deteriorate

Engineering Contradiction:
Improvesecurity controlVSAvoiduser flexibility
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent implements context-aware policy enforcement where different policies are applied based on the specific device state, application, or environment. The MDM agent evaluates multiple policies and applies only those relevant to the current context, allowing strict security controls where needed while maintaining user flexibility in other scenarios. For example, certain applications may have restricted access to enterprise resources while personal applications maintain normal functionality, achieving both security control and user flexibility through localized policy application.

Inventive Principle:
Principle #3Local quality

Data Source

PatentEP3531662B1Providing mobile device management functionalities
Publication Date: 2021.05.05 CITRIX SYSTEMS INC
  • EP3531662B1 patent drawingFigure 1
  • EP3531662B1 patent drawingFigure 2
  • EP3531662B1 patent drawingFigure 3

AI summary

Methods, systems, computer-readable media, and apparatuses for providing mobile device management functionalities are presented. In various embodiments, a mobile device management agent may monitor state information associated with a mobile computing device. The monitored state information may be analyzed on the mobile computing device and/or by one or more policy management servers. In some instances, the one or more policy management servers may provide management information to the mobile computing device, and the management information may include one or more commands (which may, e.g., cause the mobile computing device to enforce one or more policies) and/or one or more policy updates. Subsequently, one or more policies may be enforced on the mobile computing device based on the monitored state information and/or based on the management information.